Hello,
syzbot found the following issue on:
HEAD commit: fcaeecb8b0cd Merge tag 'probes-fixes-v7.2-rc6' of git://gi..
git tree: upstream
console output:
https://syzkaller.appspot.com/x/log.txt?x=143777b9580000
kernel config:
https://syzkaller.appspot.com/x/.config?x=84b3039e8461eef5
dashboard link:
https://syzkaller.appspot.com/bug?extid=4b2308d475459b29b9aa
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
CC: [
anna-...@linutronix.de fred...@kernel.org linux-...@vger.kernel.org tg...@kernel.org]
Unfortunately, I don't have any reproducer for this issue yet.
Downloadable assets:
disk image:
https://storage.googleapis.com/syzbot-assets/b6ed93a25895/disk-fcaeecb8.raw.xz
vmlinux:
https://storage.googleapis.com/syzbot-assets/50fd2cb8e282/vmlinux-fcaeecb8.xz
kernel image:
https://storage.googleapis.com/syzbot-assets/d2b1951755bc/bzImage-fcaeecb8.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by:
syzbot+4b2308...@syzkaller.appspotmail.com
==================================================================
BUG: KCSAN: data-race in hrtimer_reprogram / print_cpu
write to 0xffff888237d1b768 of 8 bytes by task 23148 on cpu 1:
__hrtimer_reprogram kernel/time/hrtimer.c:713 [inline]
hrtimer_reprogram+0x183/0x290 kernel/time/hrtimer.c:899
hrtimer_start_range_ns_user+0xfa/0x150 kernel/time/hrtimer.c:1581
hrtimer_start_expires_user include/linux/hrtimer.h:248 [inline]
common_hrtimer_rearm+0x85/0x90 kernel/time/posix-timers.c:296
__posixtimer_deliver_signal kernel/time/posix-timers.c:317 [inline]
posixtimer_deliver_signal+0x103/0x350 kernel/time/posix-timers.c:348
dequeue_signal+0x296/0x370 kernel/signal.c:660
get_signal+0x356/0xf10 kernel/signal.c:2926
arch_do_signal_or_restart+0x96/0x480 arch/x86/kernel/signal.c:337
__exit_to_user_mode_loop kernel/entry/common.c:66 [inline]
exit_to_user_mode_loop+0x15d/0x8c0 kernel/entry/common.c:101
__exit_to_user_mode_prepare include/linux/irq-entry-common.h:207 [inline]
syscall_exit_to_user_mode_prepare include/linux/irq-entry-common.h:230 [inline]
syscall_exit_to_user_mode include/linux/entry-common.h:318 [inline]
do_syscall_64+0x23c/0x3c0 arch/x86/entry/syscall_64.c:100
entry_SYSCALL_64_after_hwframe+0x77/0x7f
read to 0xffff888237d1b768 of 8 bytes by task 23167 on cpu 0:
print_cpu+0x2fb/0x5d0 kernel/time/timer_list.c:129
timer_list_show+0x107/0x170 kernel/time/timer_list.c:287
seq_read_iter+0x5f6/0x8f0 fs/seq_file.c:273
proc_reg_read_iter+0x110/0x180 fs/proc/inode.c:299
copy_splice_read+0x47a/0x6b0 fs/splice.c:362
do_splice_read fs/splice.c:980 [inline]
splice_direct_to_actor+0x261/0x680 fs/splice.c:1084
do_splice_direct_actor fs/splice.c:1202 [inline]
do_splice_direct+0x119/0x1a0 fs/splice.c:1228
do_sendfile+0x37d/0x640 fs/read_write.c:1371
__do_sys_sendfile64 fs/read_write.c:1432 [inline]
__se_sys_sendfile64 fs/read_write.c:1418 [inline]
__x64_sys_sendfile64+0x105/0x150 fs/read_write.c:1418
x64_sys_call+0x2dc4/0x3020 arch/x86/include/generated/asm/syscalls_64.h:41
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
do_syscall_64+0x136/0x3c0 arch/x86/entry/syscall_64.c:94
entry_SYSCALL_64_after_hwframe+0x77/0x7f
value changed: 0x00000058582f75dc -> 0x00000058582bc12e
Reported by Kernel Concurrency Sanitizer on:
CPU: 0 UID: 0 PID: 23167 Comm: syz.0.7065 Not tainted syzkaller #0 PREEMPT(lazy)
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/24/2026
==================================================================
---
This report is generated by a bot. It may contain errors.
See
https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at
syzk...@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup